A data encryption transmission system for unmanned aerial vehicles

By adopting a modular design for the UAV data encryption transmission system, the channel status and data type are monitored in real time, and the encryption strategy and parameters are dynamically adjusted. This solves the security problem that existing technologies cannot adapt to complex environments, and achieves a balance between data transmission security and efficiency.

CN120980520BActive Publication Date: 2026-06-02HANGYI (SHENZHEN) DRONE TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HANGYI (SHENZHEN) DRONE TECH CO LTD
Filing Date
2025-10-17
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing UAV data transmission solutions lack real-time monitoring and dynamic response mechanisms for actual security indicators during data transmission. This results in encryption strategies being unable to adapt to complex and ever-changing operating environments and dynamic security requirements, and failing to achieve a balance between data security and system operating efficiency.

Method used

A UAV data encryption transmission system was designed, including a data acquisition module, an encryption strategy selection module, an encryption parameter setting module, and a real-time encryption control module. By monitoring the channel status and data type in real time, the encryption strategy and parameters are dynamically adjusted to achieve adaptive encryption protection.

Benefits of technology

It enables dynamic adjustment of encryption strategies based on data type and channel status, improving the security and efficiency of data transmission, reducing the consumption of UAV computing resources and endurance, and adapting to diverse data encryption transmission needs in complex scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120980520B_ABST
    Figure CN120980520B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of unmanned aerial vehicle data transmission, and discloses an unmanned aerial vehicle data encryption transmission system. A data acquisition module of the system acquires unmanned aerial vehicle data to be transmitted and current channel state information, and sends the data to an encryption strategy selection module; the encryption strategy selection module selects a target encryption strategy containing an encryption algorithm type, an initial encryption strength and an initial key update period from a pre-stored encryption strategy library according to the unmanned aerial vehicle data type and the channel state information; an encryption parameter setting module sets the initial encryption strength, the initial key update period and an initial data block length as system initial operation parameters according to the target encryption strategy; and a real-time encryption control module monitors actual safety indexes of data transmission in real time, dynamically adjusts system operation parameters according to the deviation of the actual safety indexes from preset safety threshold values. The system realizes on-demand selection of encryption strategies and dynamic optimization of parameters, and takes into account data transmission safety and system operation efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of unmanned aerial vehicle (UAV) data transmission technology, specifically to an encrypted UAV data transmission system. Background Technology

[0002] With the rapid development of drone technology, its applications have expanded from traditional aerial surveying and mapping to multiple fields such as agricultural plant protection, power line inspection, emergency rescue, and logistics transportation. This has led to a surge in demand for massive data transmission during drone operations. This data not only includes the drone's own flight parameters, such as altitude, speed, and attitude, but also often involves sensitive information from the operational scenario, such as detailed structural data of power facilities, precise soil moisture information for agricultural plots, and the distribution of personnel in emergency rescue areas. If this data is leaked, tampered with, or lost during transmission, it will not only affect the normal operation of drone missions but may also lead to serious safety hazards and economic losses.

[0003] The operating environment of drones is often complex and variable, leading to significant instability in the channel conditions upon which data transmission depends. In open plains, the channel may maintain good connectivity; however, in densely populated urban areas, mountainous valleys, or industrial areas with strong electromagnetic interference, the channel is prone to signal attenuation, noise interference, and bandwidth fluctuations. Currently, most drone data encryption transmission solutions on the market employ a fixed encryption strategy. This means that regardless of whether the data to be transmitted is ordinary flight parameters or highly sensitive operational data, and regardless of whether the channel conditions are stable or fluctuating, a uniform encryption algorithm, encryption strength, and key update cycle are used for encrypted data transmission.

[0004] This fixed encryption strategy has significant limitations. When facing highly sensitive data transmission needs with poor channel conditions, a fixed low encryption strength may not meet the data security requirements and is insufficient to defend against potential network attacks and data theft. Conversely, when transmitting low-sensitivity, ordinary data with good channel conditions, using a high-strength encryption strategy would excessively consume the drone's computing resources and power, leading to reduced flight endurance. Furthermore, the overly complex encryption process could cause data transmission delays, affecting the real-time issuance of operational instructions and timely data feedback. In addition, a fixed key update cycle cannot be adjusted according to actual security risks during data transmission. When abnormal channel fluctuations occur, potentially revealing security vulnerabilities, shortening the key update cycle cannot improve data transmission security. Conversely, when the channel condition is stable over a long period with low security risks, a fixed short-cycle key update would increase unnecessary system overhead.

[0005] Existing encrypted transmission schemes lack real-time monitoring and dynamic response mechanisms for actual security indicators during data transmission. During transmission, the security threats faced by data are dynamic and constantly changing. Sudden increases in electromagnetic interference in the external environment or the access of unknown network nodes can instantly raise the risk of data interception or tampering. Fixed encryption strategies cannot detect these changes in a timely manner and adjust accordingly, leaving UAV data transmission in a passive security protection state. This makes it difficult to adapt to complex and ever-changing operating environments and dynamic security requirements, and it fails to achieve a balance between data transmission security and system efficiency. This severely restricts the reliable application and further promotion of UAVs in various complex scenarios. Summary of the Invention

[0006] The purpose of this invention is to provide an encrypted data transmission system for unmanned aerial vehicles (UAVs) to solve the problems mentioned in the background art.

[0007] To achieve the above objectives, the present invention provides a drone data encryption transmission system, the system comprising:

[0008] The module includes a data acquisition module, an encryption strategy selection module, an encryption parameter setting module, and a real-time encryption control module.

[0009] The data acquisition module is used to acquire the UAV data to be transmitted and the current channel status information, and send the UAV data and the channel status information to the encryption strategy selection module;

[0010] The encryption strategy selection module is used to select a target encryption strategy from a pre-stored encryption strategy library based on the type of UAV data and the channel state information. The encryption strategy library contains encryption strategies corresponding to various data types and channel states. The target encryption strategy includes encryption algorithm type, initial encryption strength, and initial key update cycle.

[0011] The encryption parameter setting module is used to set a set of operating parameters of the UAV data encryption system as initial operating parameters according to the target encryption strategy, wherein the set of operating parameters includes the initial encryption strength, the initial key update cycle and the initial data block length;

[0012] The real-time encryption control module is used to monitor the actual security indicators of data transmission in real time, and dynamically adjust the set of operating parameters of the UAV data encryption system according to the deviation between the actual security indicators and the preset security threshold.

[0013] Preferably, the data acquisition module is specifically used to collect the type, size, priority level, and real-time channel bandwidth, channel bit error rate, and channel interference intensity of the UAV data.

[0014] Preferably, the method by which the encryption strategy selection module determines the target encryption strategy based on the type of UAV data and the channel state information includes:

[0015] Identify the sensitivity level and real-time channel quality level of the UAV data;

[0016] Based on the sensitivity level and the channel quality level query strategy mapping table, select the corresponding encryption algorithm type and the initial encryption strength.

[0017] Preferably, the encryption parameter setting module is further configured to dynamically calculate real-time adaptive coefficients based on the channel state information, wherein the real-time adaptive coefficients include bandwidth adaptive coefficients, bit error adaptive coefficients, and interference adaptive coefficients.

[0018] The encryption parameter setting module integrates the real-time adaptive coefficient with the initial operating parameters to generate dynamic operating parameters, which include dynamic encryption strength, dynamic key update cycle, and dynamic data block length.

[0019] Preferably, the actual security indicators monitored in real time by the real-time encryption control module include real-time encryption latency, real-time data integrity rate, and real-time anti-cracking level;

[0020] The real-time encryption control module compares the actual security indicators with the preset security threshold to obtain deviation information, and uses a feedback control algorithm to adjust the dynamic operating parameters based on the deviation information.

[0021] Preferably, the method by which the feedback control algorithm adjusts the dynamic operating parameters based on the deviation information includes:

[0022] The actual safety indicators at multiple consecutive moments are obtained to form a safety indicator sequence;

[0023] A deviation sequence is calculated based on the safety index sequence and the preset safety threshold;

[0024] Predict changes in safety trends based on the deviation sequence;

[0025] The dynamic operating parameters are adjusted based on the changes in the safety trend.

[0026] Preferably, when adjusting the dynamic operating parameters, the real-time encryption control module is further configured to determine whether a successive adjustment mechanism needs to be initiated, the method comprising:

[0027] Get the current running parameters;

[0028] Calculate the difference between the current operating parameters and the target operating parameters;

[0029] If the difference exceeds the set threshold, the operating parameters will be adjusted step by step according to the preset adjustment step size.

[0030] Preferably, the system further includes a key management module, used to generate an encryption key according to the target encryption strategy output by the encryption strategy selection module, and update the key based on the adjustment instructions output by the real-time encryption control module.

[0031] Preferably, the key management module is also used to coordinate with the real-time encryption control module to dynamically calculate the key update frequency based on the deviation between the actual security indicator and the preset security threshold.

[0032] Preferably, the real-time encryption control module is further configured to trigger an alarm signal and switch to a backup encryption strategy when the actual security indicator deviates from the preset security threshold by more than the tolerance range.

[0033] Compared with the prior art, the beneficial effects of the present invention are:

[0034] The data acquisition module can simultaneously collect the UAV data to be transmitted and the current channel status information, and send both types of key information to the encryption strategy selection module at the same time. This design breaks the limitation of traditional solutions that only focus on the data itself and ignore the transmission channel status. By acquiring channel status information in real time, the selection of subsequent encryption strategies is no longer divorced from the actual transmission environment, laying the foundation for achieving encryption protection adapted to the transmission scenario. This provides sufficient realistic basis for the formulation of encryption strategies and avoids the problem of adopting inappropriate encryption strategies due to a lack of knowledge of the channel status.

[0035] The encryption strategy selection module selects a target encryption strategy from a pre-stored encryption strategy library based on the type of UAV data and channel status information. This library covers encryption strategies corresponding to various data types and channel states, and the target encryption strategy specifies the encryption algorithm type, initial encryption strength, and initial key update cycle. This means the system can adopt differentiated encryption protection measures for different types of data. For highly sensitive operational data, strategies with higher encryption strength and more reliable algorithms can be selected; for ordinary flight parameter data, relatively lightweight encryption algorithms and appropriate encryption strengths can be chosen, achieving a precise match between encryption strategies and data sensitivity. Simultaneously, by combining encryption strategy selection with channel status information, when the channel status is good and interference is minimal, a low-resource-consumption encryption strategy can be selected while ensuring security, avoiding unnecessary resource waste. When the channel status is poor, with strong interference or potential security risks, a higher-strength encryption strategy with stronger anti-interference capabilities can be automatically selected to ensure data transmission security in complex channel environments. This truly achieves "on-demand selection" of encryption strategies, balancing data security and system operating efficiency.

[0036] The encryption parameter setting module sets a set of initial operating parameters for the UAV data encryption system based on the target encryption strategy. This set of parameters includes not only the initial encryption strength and initial key update cycle, but also a newly added key parameter: the initial data block length. Appropriately setting the data block length can further optimize encryption and transmission efficiency. For example, when the channel bandwidth is wide, appropriately increasing the data block length can reduce the number of blocks and lower the overhead during encryption; conversely, when the channel bandwidth is narrow or fluctuates significantly, decreasing the data block length helps improve the anti-interference capability of data transmission and reduces the risk of overall transmission efficiency degradation due to single-block data transmission failure. Through the initial setting of multi-dimensional operating parameters, the system can perform encrypted transmission in an optimal state adapted to the current data type and channel conditions from the startup phase.

[0037] The real-time encryption control module monitors the actual security indicators of data transmission in real time and dynamically adjusts the system's operating parameters based on the deviation between the actual security indicators and preset security thresholds, constructing a dynamic and adaptive encryption protection mechanism. During data transmission, the actual security indicators may fluctuate due to factors such as sudden changes in channel conditions and increased external security threats. When the actual security indicators fall below the preset security threshold, indicating an increased security risk to data transmission, the module automatically adjusts operating parameters, such as increasing encryption strength, shortening the key update cycle, and optimizing data block length, to enhance encryption protection capabilities and resist potential security threats. When the actual security indicators are higher than the preset security threshold and the channel condition remains stable, the module appropriately reduces encryption strength, extends the key update cycle, or adjusts the data block length to improve transmission efficiency and reduce system resource consumption. This dynamic adjustment mechanism enables the system to continuously adapt to changes in real-time security status and channel environment during data transmission, avoiding the imbalance between security and efficiency inherent in traditional fixed encryption strategies.

[0038] The entire system's modules work collaboratively, forming a complete closed loop from data and channel information acquisition, intelligent encryption strategy selection, precise configuration of operating parameters, to real-time dynamic adjustment. Compared to traditional solutions, this system can not only formulate reasonable encryption schemes based on data type and initial channel state, but also continuously monitor and flexibly adjust the security status during transmission. This ensures the secure transmission of data of varying sensitivities in various channel environments while minimizing the consumption of UAV computing resources and endurance during encryption. It also improves the real-time performance and stability of data transmission, meeting the diverse data encryption transmission needs of UAVs in complex scenarios such as agriculture, power, and emergency rescue, providing a more reliable security guarantee for the further promotion and application of UAV technology. Attached Figure Description

[0039] Figure 1 This is a schematic diagram illustrating the working principle of the UAV data encryption transmission system described in this invention.

[0040] Figure 2 A flowchart for determining the target policy of the encryption policy selection module;

[0041] Figure 3 This is a diagram illustrating data acquisition and channel state analysis.

[0042] Figure 4 A flowchart for the dynamic parameter generation of the encryption parameter setting module;

[0043] Figure 5 A diagram showing the adjustment of encryption parameters and security monitoring. Detailed Implementation

[0044] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0045] Please see Figure 1 The present invention provides an encrypted data transmission system for unmanned aerial vehicles (UAVs), the system comprising: a data acquisition module, an encryption strategy selection module, an encryption parameter setting module, and a real-time encryption control module.

[0046] The data acquisition module is responsible for collecting the UAV data to be transmitted and the current channel status information, and sending this information to the encryption strategy selection module. The encryption strategy selection module selects a target encryption strategy from a pre-stored encryption strategy library based on the type of UAV data and the channel status information. This target encryption strategy includes the encryption algorithm type, initial encryption strength, and initial key update cycle. The encryption parameter setting module sets a set of operating parameters of the UAV data encryption system as initial operating parameters according to the target encryption strategy. This set of operating parameters includes the initial encryption strength, initial key update cycle, and initial data block length. The real-time encryption control module monitors the actual security indicators of data transmission in real time and dynamically adjusts a set of operating parameters of the UAV data encryption system based on the deviation between the actual security indicators and the preset security threshold. This system achieves adaptive control of data encryption through modular design, ensuring secure transmission under different channel conditions.

[0047] Example 1: See Figure 2The system interacts with the flight control system's data bus via embedded sensors, continuously acquiring the UAV data stream and its associated attributes, which encompass multiple dimensions such as data type, data size, and priority level. Data types are categorized into flight control commands, remote sensing image data, equipment status logs, and mission payload information. Data size is measured in bytes, and priority levels are divided into four levels: urgent, high, medium, and low, based on the data's criticality to flight safety and mission execution. Simultaneously, the data acquisition module extracts physical layer channel characteristics in real time via a wireless communication interface. Acquisition parameters include channel bandwidth, channel bit error rate, and channel interference intensity. Channel bandwidth reflects currently available spectrum resources, the channel bit error rate is calculated using a bit error detection algorithm, and the channel interference intensity is obtained by comparing the received signal strength indicator with the background noise level. All this acquired data is preprocessed to form standardized data frames, which are then transmitted to the encryption strategy selection module via an internal communication link.

[0048] Upon receiving information from the data acquisition module, the encryption strategy selection module immediately initiates the strategy decision-making process. Its built-in processor first parses the UAV data, identifying its sensitivity level. Sensitivity level determination is based on a combination of data type and priority rules. For example, flight control commands and authentication information are automatically classified as the highest sensitivity level, while ordinary environmental monitoring data may be classified as medium or low. Simultaneously, the module performs a comprehensive analysis of channel state information to assess the real-time channel quality level. The analysis process employs a multi-parameter weighted algorithm, mapping channel bandwidth, bit error rate, and interference intensity to discrete quality levels. These quality levels are divided into four grades: excellent, good, medium, and poor. High bandwidth combined with low bit error rate corresponds to the excellent level, while low bandwidth combined with high interference corresponds to the poor level. After classification, the module accesses a pre-stored strategy mapping table, which is stored in non-volatile memory as a two-dimensional matrix. The row index of the matrix corresponds to the sensitivity level, and the column index corresponds to the channel quality level. Each matrix cell stores a pre-configured encryption algorithm type and a recommended initial encryption strength value. The encryption algorithm types include symmetric encryption algorithms such as AES, DES, and ChaCha20. The initial encryption strength is reflected in the combination of key length and number of rounds of computation. The query process locates the corresponding matrix unit by matching the current sensitivity level and channel quality level, extracts the encryption algorithm type and initial encryption strength as core parameters, and supplements the suggested value of the initial key update cycle based on historical transmission performance data. Finally, the target encryption strategy is packaged and output to the downstream module.

[0049] The construction of the policy mapping table relies on a combination of domain knowledge and experimental data. Its design follows a balance between security and transmission efficiency. For high-sensitivity data with poor channel quality, the mapping table may specify a high-strength encryption algorithm and a longer key update cycle to ensure security, but at the cost of some real-time performance. Conversely, for low-sensitivity data with good channel quality, a lightweight encryption algorithm and a shorter update cycle may be chosen to improve throughput. This table is initialized using a configuration tool before system deployment and supports dynamic updates via a management interface during operation to adapt to new threats or changes in communication standards. The encryption policy selection module is fully automated, requiring no manual intervention, with decision latency controlled within milliseconds, meeting the real-time requirements of UAV data transmission. The data acquisition module provides raw input, while the encryption policy selection module performs the core analysis functions. During system operation, these two modules continuously work together to ensure that the encryption policy responds to changes in the data transmission environment, thereby maintaining an optimal balance between security and performance under dynamic conditions.

[0050] See Figure 3 This diagram showcases key data from a UAV data encryption transmission system. The top-left subplot illustrates the variation of channel bandwidth over time, reflecting the dynamic changes in available spectrum resources during communication. The top-right subplot shows fluctuations in the channel bit error rate, calculated using a bit error detection algorithm, which directly impacts data transmission reliability. The bottom-left subplot presents variations in channel interference intensity, determined by comparing the received signal strength indicator with background noise levels, significantly affecting communication quality. The bottom-right subplot displays the distribution of different types of UAV data collected, including flight control commands, remote sensing image data, equipment status logs, and mission payload information. The different types and priority levels of these data directly influence the selection of encryption strategies.

[0051] Example 2: See Figure 4Upon receiving the target encryption policy from the encryption policy selection module, the encryption parameter setting module immediately initiates the parameter configuration process. This module first parses the basic parameters contained in the target encryption policy, such as the initial encryption strength, initial key update cycle, and initial data block length. Simultaneously, it continuously acquires the latest channel state information from the data acquisition module. This channel state information includes dynamic variables such as real-time channel bandwidth, channel bit error rate, and channel interference intensity. These variables are updated at a fixed sampling frequency through a dedicated communication interface. Based on these real-time channel parameters, the encryption parameter setting module calculates three types of adaptive coefficients: the bandwidth adaptive coefficient reflects the degree of matching between the current available transmission capacity and the ideal state; the bit error rate adaptive coefficient characterizes the reliability level of channel transmission; and the interference adaptive coefficient quantifies the impact of environmental noise on signal quality. Each coefficient is calculated using a normalization method, mapping the original channel data to a value range of 0 to 1, where 1 represents the optimal condition and 0 represents the worst condition. For example, the bandwidth adaptive coefficient can be obtained by the ratio of the current bandwidth to the maximum theoretical bandwidth, while the bit error rate adaptive coefficient is derived from the inverse relationship between the bit error rate and the acceptable maximum bit error rate.

[0052] The calculated real-time adaptive coefficients are immediately fused with the initial operating parameters to generate dynamic operating parameters suitable for the current environment. These dynamic parameters include dynamic encryption strength, dynamic key update cycle, and dynamic data block length. The generation of dynamic encryption strength comprehensively considers the weighted relationship between the initial encryption strength and the three adaptive coefficients. When bandwidth conditions are favorable and the bit error rate is low, the encryption strength is appropriately increased; conversely, in environments with strong interference, the strength may be moderately reduced to ensure transmission timeliness. The determination of the dynamic key update cycle incorporates the interaction between the initial cycle value and the bit error rate adaptive coefficient. High-frequency bit error environments typically trigger more frequent key updates to enhance security. The adjustment of the dynamic data block length mainly relies on the bandwidth adaptive coefficient. Under narrower bandwidth conditions, a smaller data block length is used to reduce transmission latency; under wider bandwidth conditions, larger data blocks are allowed to improve throughput efficiency. All these dynamic parameters are generated through a specialized parameter fusion algorithm. This algorithm employs a multi-input single-output mapping model to ensure that the output parameters fully reflect the balance between channel conditions and security requirements.

[0053] The real-time encryption control module operates in parallel with security monitoring functions. This module collects actual security metrics via probes deployed along the encrypted data transmission path. These metrics include real-time encryption latency, real-time data integrity rate, and real-time anti-cracking level. Real-time encryption latency measures the time interval from data input to the encryption module to the completion of encryption processing using a timestamp mechanism. Real-time data integrity rate calculates the proportion of successfully transmitted data packets using a checksum comparison algorithm. The real-time anti-cracking level is dynamically evaluated based on the strength of the currently used encryption algorithm and the key length. All security metrics are sampled at millisecond-level frequencies and temporarily stored in a circular buffer, forming continuous time-series data. The real-time encryption control module has a built-in comparator that compares these actual security metrics with preset security thresholds. These preset security thresholds are pre-configured according to different data types and application scenarios; for example, the real-time encryption latency threshold might be set to 100 milliseconds, and the real-time data integrity rate threshold might be set to 99.5%. The comparison results generate deviation information, including the absolute deviation value and the relative deviation direction.

[0054] Deviation information is input into a feedback control algorithm for processing. This algorithm employs a proportional-integral-derivative (PID) control structure, calculating the adjustment amount based on the magnitude and trend of the deviation. The proportional term processes the current instantaneous deviation, the integral term accumulates historical deviations to eliminate steady-state error, and the derivative term predicts the deviation trend to provide proactive adjustment. The algorithm outputs adjustment commands, which are sent to the encryption parameter setting module. These commands include correction values ​​for dynamic encryption strength, dynamic key update cycle, and dynamic data block length. The encryption parameter setting module updates its output dynamic operating parameters in real time based on these commands, forming a closed-loop control loop. The entire adjustment process runs continuously, enabling the system to respond quickly to changes in channel conditions and security threats, always maintaining an optimal balance between security and efficiency in the encrypted transmission process. The system achieves adaptive encrypted transmission through this dynamic parameter adjustment mechanism. The encryption parameter setting module is responsible for converting static strategies into dynamic parameters, while the real-time encryption control module ensures that these parameters always match the requirements of the actual transmission environment through continuous monitoring and feedback adjustment. The collaborative work of the two modules enables the UAV data encryption system to cope with dynamic changes in wireless channels. It avoids both the degradation of transmission performance due to over-encryption and the security risks caused by insufficient encryption, thus maintaining reliable and secure data transmission services in complex communication environments.

[0055] See Figure 5The top-left subplot illustrates the dynamic adjustment process of system operating parameters, including changes in encryption strength, key update cycle, and data block length. These parameters are adaptively adjusted based on real-time channel conditions and security requirements. The top-right subplot displays real-time monitoring results of security indicators, including encryption latency, data integrity rate, and anti-cracking level. These indicators reflect the actual security performance of the system. The bottom-left subplot presents the calculation process of adaptive coefficients, including bandwidth adaptive coefficient, bit error rate adaptive coefficient, and interference adaptive coefficient. These coefficients are normalized to map the original channel data to a value range of 0 to 1, providing a basis for parameter adjustment. The bottom-right subplot shows the relationship between encryption strength and encryption latency, reflecting the trade-off between security and performance.

[0056] Example 3: The feedback control algorithm needs to process the continuous data stream from the real-time encryption control module to make accurate parameter adjustment decisions. This algorithm first establishes a sliding data window to store actual security indicators at multiple consecutive moments. These actual security indicators include three core parameters: real-time encryption latency, real-time data integrity rate, and real-time anti-cracking level. These parameters are obtained from the encryption processing unit and the channel monitoring unit at fixed sampling intervals, and each parameter value is marked with a precise timestamp. The size of the data window is dynamically configured according to the system's processing capacity, typically retaining historical data from the most recent dozens of sampling periods, forming a security indicator sequence with temporal characteristics. This sequence not only records the instantaneous values ​​of the parameters but also implicitly contains the patterns and trends of parameter changes over time. The security indicator sequence is compared with a preset security threshold to generate a deviation sequence. The preset security threshold is pre-set according to different application scenarios and stored in a configuration file; for example, an upper limit threshold may be set for real-time encryption latency, and a lower limit threshold may be set for real-time data integrity rate. The comparison operation is completed by calculating the difference between each data point and the corresponding threshold, and the resulting deviation values ​​form a new time series, i.e., the deviation sequence. Each data point in the deviation sequence contains not only the magnitude of the deviation but also its direction; a positive deviation indicates that the actual value is higher than the threshold, while a negative deviation indicates that the actual value is lower than the threshold. This deviation sequence serves as the foundational data source for subsequent trend analysis.

[0057] Predicting security trend changes based on deviation sequences is the core function of the feedback control algorithm. The prediction process uses a weighted moving average method to analyze the evolution of the sequence. This method assigns different weight coefficients to each data point in the deviation sequence, with recent data points receiving higher weights and historical data points having progressively decreasing weights. The trend indicator value is obtained through weighted calculation. The trend prediction result is reflected in three dimensions: the direction of change indicates whether the parameter will develop in a better or worse direction; the magnitude of change estimates the severity of the parameter change; and the rate of change reflects the rate of parameter change. These prediction results are combined to form a forward-looking judgment on the system's security status. The process of adjusting dynamic operating parameters based on security trend changes is achieved through parameter mapping rules, which establish a correspondence between trend prediction results and parameter adjustment amounts. For dynamic encryption strength parameters, the strength value is appropriately increased when the prediction shows a deteriorating security status, and appropriately decreased to improve efficiency when the prediction shows an improving status. The adjustment of the dynamic key update cycle follows a similar logic: the cycle is shortened to improve security when the security trend worsens, and extended to reduce system overhead when the trend improves. The adjustment of the dynamic data block length is more complex, requiring a balance between security trends and transmission efficiency. The entire adjustment process is expressed through the following mathematical relationship:

[0058]

[0059] in: This indicates the adjustment amount of the operating parameters. The system gain coefficient. , , These are the weighting coefficients for the differential, integral, and proportional terms, respectively. This represents the instantaneous deviation value in the deviation sequence. Indicates the rate of change of deviation. This represents the cumulative deviation. This adjustment formula considers the current state, historical accumulation, and trend of the deviation, ensuring that parameter adjustments are both timely and stable. The execution cycle of the feedback control algorithm is synchronized with the data sampling cycle, completing a full closed-loop control from data acquisition to parameter adjustment in each sampling cycle. The algorithm employs an incremental adjustment strategy, making only small corrections to the operating parameters each time to avoid system oscillations caused by sudden parameter changes. All adjustment operations are recorded in the audit log, including adjustment time, parameter values ​​before adjustment, parameter values ​​after adjustment, and reasons for adjustment, providing data support for system performance analysis and optimization. Through this refined feedback control mechanism, the UAV data encryption system can adapt to complex and ever-changing transmission environments, optimizing transmission performance while ensuring security.

[0060] Taking a fixed-wing UAV performing a border patrol mission as an example, its onboard high-definition video surveillance system continuously collects and transmits real-time video stream data. The flight area has complex terrain and intermittent signal interference sources, causing periodic fluctuations in wireless channel conditions. The initial system configuration uses the AES-192 encryption algorithm, with a key update cycle of 120 seconds and a data block length of 1536 bytes. During mission execution, the real-time encryption control module collects security indicator data once per second. At the 18-minute mark, the UAV enters a canyon area with strong signal interference. The encryption control module begins recording continuous time-series security indicator data, forming a security indicator sequence that includes real-time encryption latency, data integrity rate, and anti-cracking level. This sequence is stored in a circular buffer, retaining historical data from the most recent 60 sampling points. Each data point has a precise timestamp and a corresponding channel state marker, forming a data set with temporal characteristics.

[0061] The security indicator sequence is compared point-by-point with preset security thresholds to generate a corresponding deviation sequence. The preset thresholds include an 80-millisecond encryption latency upper limit, a 98.5% data integrity rate lower limit, and a medium anti-cracking level requirement. During the comparison, the system calculates the absolute and relative deviations between the actual value of each sampling point and the threshold, and arranges these deviation values ​​in chronological order to form a deviation sequence. This sequence records not only the magnitude of the deviation but also its direction and duration. When predicting security trends based on the deviation sequence, the system uses a weighted moving average method to analyze data change patterns. This method assigns higher weights to recent data, with historical data weights gradually decreasing, and calculates the trend indicator by calculating the weighted average. The prediction results show three clear trends: encryption latency shows a continuous upward trend, data integrity rate remains stable but close to the lower threshold, and the anti-cracking level remains stable due to the sustained encryption strength. These trend indicators are quantified into numerical forms for subsequent parameter adjustment decisions.

[0062] When adjusting dynamic operating parameters based on changes in security trends, the system establishes a mapping relationship between trend prediction results and parameter adjustment amounts. For a continuously increasing encryption latency trend, the system appropriately reduces the dynamic encryption strength from 192 bits to 176 bits; when the data integrity rate approaches the threshold, the dynamic data block length is shortened to 1408 bytes to improve transmission reliability; the dynamic key update cycle remains unchanged to ensure security continuity. All adjustments are performed incrementally, with each adjustment controlled within 5% to avoid system oscillations caused by sudden parameter changes. During the adjustment process, the system continuously monitors changes in the deviation sequence. After each parameter adjustment, the system reassesses the security trend and updates the prediction results based on the new deviation sequence. The entire adjustment process forms a closed-loop control, gradually bringing the operating parameters closer to their optimal values ​​through multiple iterations. After three adjustment cycles, the encryption latency drops back to 85 milliseconds, the data integrity rate stabilizes at 98.7%, and the system reaches a new equilibrium state. All adjustment operations are recorded in the system log, including information such as adjustment time, adjustment parameters, adjustment basis, and adjustment results. These records provide data support for subsequent system performance analysis and optimization. Through this time-based prediction-based adjustment mechanism, the UAV data encryption system can maintain adaptive adjustment capabilities in complex electromagnetic environments, ensuring the best balance between data transmission security and real-time performance.

[0063] Example 4: In the actual operation of the UAV data encryption transmission system, the real-time encryption control module needs to handle the stability and smoothness of parameter adjustments. When the system detects a significant difference between the current operating parameters and the target operating parameters, it will initiate a successive adjustment mechanism to avoid system oscillations caused by parameter mutations. Consider a specific application scenario: A certain type of UAV is performing a high-definition video surveillance task. The initial configuration of the data transmission system is 128-bit encryption strength, 300-second key update cycle, and 1024-byte data block length. Due to sudden electromagnetic interference causing a degradation in channel quality, the real-time encryption control module calculates new target operating parameters based on security index evaluation: 192-bit encryption strength, 180-second key update cycle, and 512-byte data block length. The system first obtains the actual values ​​of the current operating parameters. These parameter values ​​are directly read from the output register of the encryption parameter setting module and stored in memory in the form of a structure. The difference between the current parameter and the target parameter is then calculated as a relative percentage. For example, the difference in encryption strength is (192-128) / 128=50%, the difference in key update cycle is (300-180) / 300=40%, and the difference in data block length is (1024-512) / 1024=50%. The system's preset threshold is 20%. When the difference of any parameter exceeds this threshold, the successive adjustment mechanism is activated.

[0064] The adjustment process proceeds step-by-step according to preset adjustment step sizes. The system sets different adjustment step sizes and adjustment cycles for each type of parameter. The adjustment step size for encryption strength is 16 bits, the adjustment step size for key update cycle is 60 seconds, and the adjustment step size for data block length is 128 bytes. The adjustment cycle is set to 10 seconds, meaning that the parameters are fine-tuned every 10 seconds. The entire adjustment process is recorded; see Table 1.

[0065] Table 1: Record of Successive Adjustments to Operating Parameters

[0066]

[0067] During parameter adjustment, the key management module works concurrently. This module generates an encryption key based on the target encryption strategy initially output by the encryption strategy selection module. Key generation employs a key derivation function based on a hardware true random number generator to produce key material that meets the current encryption strength requirements. When the real-time encryption control module outputs an adjustment command, the key management module first verifies the integrity and authenticity of the command, and then updates the key according to the command requirements. The update operation falls into two categories: for key updates caused by changes in encryption strength, a completely new key needs to be generated; for updates involving only changes in the update cycle, a key rotation method may be used to continue using the existing key but shorten its validity period.

[0068] At the end of each adjustment cycle, the system reassesses the parameter differences. If the differences still exceed the threshold, the next round of adjustment continues until the current parameters gradually approach the target value. This gradual adjustment method ensures the stability of system operation and avoids data transmission interruptions or performance fluctuations caused by sudden parameter changes. Throughout the adjustment process, the key management module maintains close collaboration with the real-time encryption control module to ensure that key updates and parameter adjustments are synchronized, maintaining the continuity of encryption security. The system also has an adjustment interruption mechanism. If channel conditions change significantly again during the adjustment process, the system will pause the current adjustment sequence, recalculate the target parameters, and start a new adjustment process. All adjustment operations are recorded in the security log, including the adjustment time, parameter values ​​before adjustment, parameter values ​​after adjustment, adjustment reasons, and related key update records. This log information provides complete audit clues for system maintenance and troubleshooting. Through this successive adjustment mechanism, the UAV data encryption transmission system can smoothly complete the adaptive optimization of operating parameters while maintaining service continuity, ensuring data transmission security and minimizing the impact of parameter adjustment on system performance. The collaborative work of the key management module ensures timely synchronization of changes in encryption keys and system parameters, maintaining the consistency of the overall security architecture.

[0069] Example 5: In the actual operation of the UAV data encryption transmission system, the key management module and the real-time encryption control module establish a collaborative working mechanism, continuously exchanging security status information and control commands through a dedicated data channel. Consider a specific application scenario: A certain type of UAV transmits high-resolution image data while performing terrain mapping tasks. The initial configuration uses the AES-256 encryption algorithm, and the key update frequency is set to once every 30 minutes. When the UAV flies into an urban area and encounters sudden electromagnetic interference, the real-time encryption control module detects that the real-time anti-hacking level drops from the security level to a critical state, showing a significant deviation from the preset security threshold. The real-time encryption control module immediately calculates the deviation value. This calculation is based on a weighted evaluation of multi-dimensional security indicators, including the increase in real-time encryption latency, the percentage decrease in data integrity rate, and the degree of reduction in anti-hacking level. The deviation is quantified as a comprehensive score between 0 and 100, where 0 indicates full compliance with security requirements and 100 indicates a serious deviation from the security standard. The currently detected deviation reaches 65 points, significantly exceeding the normal fluctuation range set by the system. This deviation data is transmitted to the dedicated processing unit of the key management module through a secure communication link.

[0070] Upon receiving the deviation data, the key management module initiates the key update frequency calculation process. Internally, this module maintains a frequency mapping table, mapping deviation values ​​to corresponding key update frequency adjustment schemes. The frequency mapping table uses a piecewise linear mapping relationship, dividing the deviation of 0-100 into five intervals: 0-20 corresponds to the "normal" frequency interval, 21-40 to the "slight increase" interval, 41-60 to the "moderate increase" interval, 61-80 to the "high increase" interval, and 81-100 to the "urgent" frequency interval. Based on the current deviation of 65 points, the system automatically selects the "high increase" frequency interval, increasing the key update frequency from once every 30 minutes to once every 5 minutes. The frequency calculation process also considers historical deviation trends; if the deviation shows a continuous upward trend, a more aggressive frequency adjustment strategy is adopted. Simultaneously, the real-time encryption control module continuously monitors changes in security indicators. When it detects that the real-time encryption delay exceeds a preset threshold by 50% for three consecutive sampling periods, the system determines that the actual security indicators have deviated from the preset security threshold beyond the tolerance range. The tolerance range is set separately for different security indicator types: ±20% for encryption latency, -2% for data integrity rate, and -15% for anti-cracking level. The currently monitored encryption latency has reached the threshold of 150%, which is significantly beyond the tolerance range.

[0071] The system immediately triggers multi-level alarm signals, employing a layered triggering mechanism: the first level is a visual alarm, displaying a yellow warning icon and brief alarm information on the console interface; the second level is an audible alarm, emitting a specific frequency alert tone; and the third level is a digital alarm, sending standardized alarm data packets to the ground control station via a wireless data link. The alarm data packets contain detailed information such as alarm level, alarm type, trigger time, current security indicator value, and deviation degree, and are encapsulated and transmitted using a dedicated encryption format. Simultaneously with the alarm triggering, the system initiates a backup encryption strategy switching process. The switching process first queries a predefined list of backup strategies from the encryption strategy library. Backup strategies are prioritized and typically include three alternatives: the primary backup strategy uses an enhanced encryption algorithm and shortens the key update cycle; the secondary backup strategy switches to a different type of encryption algorithm; and the third backup strategy enables a redundant encryption channel. Based on current channel conditions and security threat assessment results, the system automatically selects the most suitable primary backup strategy for the switch.

[0072] The policy switching operation employs a hot-swap method to ensure uninterrupted data transmission. First, a new encryption policy instance is activated and relevant parameters are initialized. Then, the data stream is gradually redirected from the old policy to the new policy. Finally, the old policy instance is terminated after confirming the new policy's stable operation. The entire switching process is completed within 500 milliseconds, maintaining continuous encrypted data transmission throughout. The key management module works synchronously with the policy switching, immediately generating new key materials according to the new encryption policy requirements and updating the key distribution mechanism to adapt to the new encryption configuration. The system records complete alarm and switching process logs, including details of deviation calculations, frequency adjustment decision basis, alarm triggering conditions, reasons for backup policy selection, and switching time points. This log information is encrypted and stored in non-volatile memory for subsequent system analysis and optimization. Through this collaborative mechanism, the UAV data encryption system can respond quickly to security threats, enhancing protection through dynamic key update frequency adjustments and providing emergency protection through backup policy switching, ensuring reliable and secure transmission services under various abnormal conditions.

[0073] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A UAV data encryption transmission system, characterized in that, include: The module includes a data acquisition module, an encryption strategy selection module, an encryption parameter setting module, and a real-time encryption control module. The data acquisition module is used to acquire the UAV data to be transmitted and the current channel status information, and send the UAV data and the channel status information to the encryption strategy selection module; The encryption strategy selection module is used to select a target encryption strategy from a pre-stored encryption strategy library based on the type of UAV data and the channel state information. The encryption strategy library contains encryption strategies corresponding to various data types and channel states. The target encryption strategy includes encryption algorithm type, initial encryption strength, and initial key update cycle. The encryption parameter setting module is used to set a set of operating parameters of the UAV data encryption system as initial operating parameters according to the target encryption strategy, wherein the set of operating parameters includes the initial encryption strength, the initial key update cycle and the initial data block length; The real-time encryption control module is used to monitor the actual security indicators of data transmission in real time, and dynamically adjust the set of operating parameters of the UAV data encryption system according to the deviation between the actual security indicators and the preset security threshold. The encryption parameter setting module is also used to dynamically calculate real-time adaptive coefficients based on the channel state information. The real-time adaptive coefficients include bandwidth adaptive coefficients, bit error adaptive coefficients, and interference adaptive coefficients. The encryption parameter setting module integrates the real-time adaptive coefficient with the initial running parameters to generate dynamic running parameters, which include dynamic encryption strength, dynamic key update cycle and dynamic data block length. The real-time encryption control module monitors the actual security indicators including real-time encryption latency, real-time data integrity rate, and real-time anti-cracking level. The real-time encryption control module compares the actual security index with the preset security threshold to obtain deviation information, and uses a feedback control algorithm to adjust the dynamic operating parameters based on the deviation information. The method by which the feedback control algorithm adjusts the dynamic operating parameters based on the deviation information includes: The actual safety indicators at multiple consecutive moments are obtained to form a safety indicator sequence; A deviation sequence is calculated based on the safety index sequence and the preset safety threshold; Predict changes in safety trends based on the deviation sequence; The dynamic operating parameters are adjusted based on the changes in the safety trend.

2. The UAV data encryption transmission system according to claim 1, characterized in that, The data acquisition module is specifically used to collect the type, size, priority level, real-time channel bandwidth, channel bit error rate, and channel interference intensity of the UAV data.

3. The UAV data encryption transmission system according to claim 1, characterized in that, The method by which the encryption strategy selection module determines the target encryption strategy based on the type of UAV data and the channel state information includes: Identify the sensitivity level and real-time channel quality level of the UAV data; Based on the sensitivity level and the channel quality level query strategy mapping table, select the corresponding encryption algorithm type and the initial encryption strength.

4. The UAV data encryption transmission system according to claim 3, characterized in that, When adjusting the dynamic operating parameters, the real-time encryption control module is also used to determine whether a successive adjustment mechanism needs to be initiated, the method of which includes: Get the current running parameters; Calculate the difference between the current operating parameters and the target operating parameters; If the difference exceeds the set threshold, the operating parameters will be adjusted step by step according to the preset adjustment step size.

5. The UAV data encryption transmission system according to claim 1, characterized in that, It also includes a key management module, which is used to generate an encryption key according to the target encryption policy output by the encryption policy selection module, and update the key based on the adjustment instructions output by the real-time encryption control module.

6. The UAV data encryption transmission system according to claim 5, characterized in that, The key management module is also used to coordinate with the real-time encryption control module to dynamically calculate the key update frequency based on the deviation between the actual security index and the preset security threshold.

7. The UAV data encryption transmission system according to claim 1, characterized in that, The real-time encryption control module is also used to trigger an alarm signal and switch to the backup encryption strategy when the actual security indicator deviates from the preset security threshold by more than the tolerance range.